# Latest

**URL:** https://discuss.elastic.co/latest.md?page=431

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 432

---

## [Only one of the Elasticsearch Warm node is getting most of the data while shifting the data from Hot to Warm as per the ILM Policy](https://discuss.elastic.co/t/only-one-of-the-elasticsearch-warm-node-is-getting-most-of-the-data-while-shifting-the-data-from-hot-to-warm-as-per-the-ilm-policy/351064)

<div class="topic-metadata">

**Author:** [@KunwarAkanksha](https://discuss.elastic.co/u/KunwarAkanksha)\
**Replies:** 0\
**Last updated:** [January 15, 2024, 10:47am UTC](https://discuss.elastic.co/t/only-one-of-the-elasticsearch-warm-node-is-getting-most-of-the-data-while-shifting-the-data-from-hot-to-warm-as-per-the-ilm-policy/351064 "2024-01-15T10:47:22Z")

</div>

I have Multinode Cord, Master, Hot and Warm Elasticsearch Cluster, with 5 primary and 2 replica shards , but according to ILM when the Load is shifting from hot to warm, only one of the warm node is getting most of the d…

---

## [Error when recovering snapshot](https://discuss.elastic.co/t/error-when-recovering-snapshot/350640)

<div class="topic-metadata">

**Author:** [@Epic555](https://discuss.elastic.co/u/Epic555)\
**Replies:** 2\
**Last updated:** [January 15, 2024, 10:27am UTC](https://discuss.elastic.co/t/error-when-recovering-snapshot/350640 "2024-01-15T10:27:44Z")

</div>

I created a snapshot with curl from 1 cluster. When I try to recover a snapshot with curl on another cluster, 2nd Cluster cannot allocate all indices. Cluster 1 has 2 nodes, cluster 2 has 1 node. I have a file "snap-hb19…

---

## [Kibana not starting & Cluster Status Yellow](https://discuss.elastic.co/t/kibana-not-starting-cluster-status-yellow/351052)

<div class="topic-metadata">

**Author:** [@aguskhohar](https://discuss.elastic.co/u/aguskhohar)\
**Replies:** 3\
**Last updated:** [January 15, 2024, 10:27am UTC](https://discuss.elastic.co/t/kibana-not-starting-cluster-status-yellow/351052 "2024-01-15T10:27:18Z")

</div>

Hi guys, Could you help me, why my kibana not starting, and im check the cluster status Yellow? Collect in elastic Log : \[2024-01-14T22:53:17,827\]\[INFO \]\[o.e.i.m.MapperService \] \[Desktop\] \[.kibana-observability-ai-…

---

## [Get\_custom\_fields of vsphere.yml of metricbeat?](https://discuss.elastic.co/t/get-custom-fields-of-vsphere-yml-of-metricbeat/350809)

<div class="topic-metadata">

**Author:** [@morry48](https://discuss.elastic.co/u/morry48)\
**Replies:** 3\
**Last updated:** [January 15, 2024, 9:03am UTC](https://discuss.elastic.co/t/get-custom-fields-of-vsphere-yml-of-metricbeat/350809 "2024-01-15T09:03:11Z")

</div>

Does anyone know how to edit the area of "get\_custom\_fields" in the vsphere.yml(vsphere module) of metricbeat? I'm currently using version 7.7.0 and am wondering about how to configure the "get\_custom\_fields" to filter …

---

## [Error connecting to package registry : reason: self-signed certificate in certificate chain](https://discuss.elastic.co/t/error-connecting-to-package-registry-reason-self-signed-certificate-in-certificate-chain/351057)

<div class="topic-metadata">

**Author:** [@Gabin\_17](https://discuss.elastic.co/u/Gabin_17)\
**Replies:** 0\
**Last updated:** [January 15, 2024, 8:40am UTC](https://discuss.elastic.co/t/error-connecting-to-package-registry-reason-self-signed-certificate-in-certificate-chain/351057 "2024-01-15T08:40:52Z")

</div>

Hello everyone ! I have this issue when i start Kibana. I saw different solution on linux but not on windows and I work on windows Failed to fetch latest version of synthetics from registry: Error connecting to package…

---

## [I'm facing .elasticsearch.bootstrap.StartupException: java.lang.IllegalArgumentException: you cannot specify a keystore and key file](https://discuss.elastic.co/t/im-facing-elasticsearch-bootstrap-startupexception-java-lang-illegalargumentexception-you-cannot-specify-a-keystore-and-key-file/350942)

<div class="topic-metadata">

**Author:** [@bshiwanand](https://discuss.elastic.co/u/bshiwanand)\
**Replies:** 4\
**Last updated:** [January 15, 2024, 8:15am UTC](https://discuss.elastic.co/t/im-facing-elasticsearch-bootstrap-startupexception-java-lang-illegalargumentexception-you-cannot-specify-a-keystore-and-key-file/350942 "2024-01-15T08:15:22Z")

</div>

I'm trying to enable xpack security enable so that internal and external communication will happen on https instead of http so please guide me how I do that, and guide me how to resolve below error. Error: {"type": "de…

---

## [Using one device to send metricbeat data from multiple devices](https://discuss.elastic.co/t/using-one-device-to-send-metricbeat-data-from-multiple-devices/350383)

<div class="topic-metadata">

**Author:** [@Lasse\_Fisker](https://discuss.elastic.co/u/Lasse_Fisker)\
**Replies:** 2\
**Last updated:** [January 15, 2024, 8:08am UTC](https://discuss.elastic.co/t/using-one-device-to-send-metricbeat-data-from-multiple-devices/350383 "2024-01-15T08:08:42Z")

</div>

Hi I have a use case, in which I want to use one instance of metricbeat to send its own data + metricbeat data from a different instance. The scenario is as follows: Device A Has internet access Has ethernet connect…

---

## [HowTo reconfigure an ElasticAgent with an invalid Fleet-URL](https://discuss.elastic.co/t/howto-reconfigure-an-elasticagent-with-an-invalid-fleet-url/350600)

<div class="topic-metadata">

**Author:** [@m3sos](https://discuss.elastic.co/u/m3sos)\
**Replies:** 4\
**Last updated:** [January 15, 2024, 7:23am UTC](https://discuss.elastic.co/t/howto-reconfigure-an-elasticagent-with-an-invalid-fleet-url/350600 "2024-01-15T07:23:03Z")

</div>

My elastic agents are running in a kubernetes cluster (daemon set). For debugging purposes I configured a fleet server url pointing to a wiremock instance (pod only) running temporarily in the cluster too. After debuggi…

---

## [Configure elastic search query to alert when the average of Total time taken exceeds a threshold](https://discuss.elastic.co/t/configure-elastic-search-query-to-alert-when-the-average-of-total-time-taken-exceeds-a-threshold/350274)

<div class="topic-metadata">

**Author:** [@Vanya](https://discuss.elastic.co/u/Vanya)\
**Replies:** 2\
**Last updated:** [January 15, 2024, 6:02am UTC](https://discuss.elastic.co/t/configure-elastic-search-query-to-alert-when-the-average-of-total-time-taken-exceeds-a-threshold/350274 "2024-01-15T06:02:47Z")

</div>

Hi All, I am trying to write a search query for Kibana rules for it to alert when the average of the total time taken exceeds a certain thereshold. Have tried using aggegators, filters and also scripts but on testing th…

---

## [Index pattern has no field but the other index pattern is working properly, i can't also connect to mapping using curl](https://discuss.elastic.co/t/index-pattern-has-no-field-but-the-other-index-pattern-is-working-properly-i-cant-also-connect-to-mapping-using-curl/350540)

<div class="topic-metadata">

**Author:** [@Epangilinangt](https://discuss.elastic.co/u/Epangilinangt)\
**Replies:** 3\
**Last updated:** [January 15, 2024, 3:15am UTC](https://discuss.elastic.co/t/index-pattern-has-no-field-but-the-other-index-pattern-is-working-properly-i-cant-also-connect-to-mapping-using-curl/350540 "2024-01-15T03:15:18Z")

</div>

Index pattern has no field but the other index pattern is working properly, i can't also connect to mapping using curl

---

## [How to aggregate non-nested fields in a nested aggregation?](https://discuss.elastic.co/t/how-to-aggregate-non-nested-fields-in-a-nested-aggregation/351044)

<div class="topic-metadata">

**Author:** [@Chanseok](https://discuss.elastic.co/u/Chanseok)\
**Replies:** 0\
**Last updated:** [January 15, 2024, 1:33am UTC](https://discuss.elastic.co/t/how-to-aggregate-non-nested-fields-in-a-nested-aggregation/351044 "2024-01-15T01:33:05Z")

</div>

The prices.adult field in "lowest\_price" is non-nested fields in a nest. The current "lowest\_price" value is null. How can I get that value? // Aggregation code "aggs": { "destination": { "nested": { …

---

## [The logstash reload config manually not work](https://discuss.elastic.co/t/the-logstash-reload-config-manually-not-work/350895)

<div class="topic-metadata">

**Author:** [@jevonsnotes](https://discuss.elastic.co/u/jevonsnotes)\
**Replies:** 4\
**Last updated:** [January 15, 2024, 1:03am UTC](https://discuss.elastic.co/t/the-logstash-reload-config-manually-not-work/350895 "2024-01-15T01:03:54Z")

</div>

as the topic, i send the kill -SIGHUP xxx to the logstash ,but the config still same. version 8.11.3 linux: Linux CS-gxxt-tyzj-03 4.19.90-52.22.v2207.ky10.aarch64 #1 SMP Tue Mar 14 11:52:45 CST 2023 aarch64 aarch64 aar…

---

## [Creating and using custom functions in painless](https://discuss.elastic.co/t/creating-and-using-custom-functions-in-painless/351037)

<div class="topic-metadata">

**Author:** [@dat\_boi](https://discuss.elastic.co/u/dat_boi)\
**Replies:** 2\
**Last updated:** [January 15, 2024, 12:01am UTC](https://discuss.elastic.co/t/creating-and-using-custom-functions-in-painless/351037 "2024-01-15T00:01:43Z")

</div>

so here is the thing , i have this long script that define variables of type String\[\] words\_var1 = new String\[\] {'word1','word1','word1'} then i have this function that tries to assign the right word to the right doc b…

---

## [Fetch results where count of nested field is more than 1](https://discuss.elastic.co/t/fetch-results-where-count-of-nested-field-is-more-than-1/351042)

<div class="topic-metadata">

**Author:** [@Hardik\_Sharma](https://discuss.elastic.co/u/Hardik_Sharma)\
**Replies:** 0\
**Last updated:** [January 14, 2024, 11:59pm UTC](https://discuss.elastic.co/t/fetch-results-where-count-of-nested-field-is-more-than-1/351042 "2024-01-14T23:59:11Z")

</div>

So I have a mapping where "configs" is a nested field. \["configs"\]{ "type": "nested", \["properties"\]: {\[56 items\] }} Now I want to fetch docs where 'configs' have more than 1 objects. For this I am using { "scr…

---

## [Rollover not working, Filebeat default index does not have an alias](https://discuss.elastic.co/t/rollover-not-working-filebeat-default-index-does-not-have-an-alias/350655)

<div class="topic-metadata">

**Author:** [@whanklee](https://discuss.elastic.co/u/whanklee)\
**Replies:** 8\
**Last updated:** [January 14, 2024, 5:19pm UTC](https://discuss.elastic.co/t/rollover-not-working-filebeat-default-index-does-not-have-an-alias/350655 "2024-01-14T17:19:15Z")

</div>

Hello, I would like to use rollover to delete all logs, however, I always get an error message. It does not work. I can use only if turn of rollover. I do not modify anything on indexes, I use default Indexes after inst…

---

## [Elastic Detection Rules](https://discuss.elastic.co/t/elastic-detection-rules/351032)

<div class="topic-metadata">

**Author:** [@Ammar\_Mostafa](https://discuss.elastic.co/u/Ammar_Mostafa)\
**Replies:** 0\
**Last updated:** [January 14, 2024, 5:01pm UTC](https://discuss.elastic.co/t/elastic-detection-rules/351032 "2024-01-14T17:01:48Z")

</div>

I want to make a rule that trigger an alert when The Ids Generates certain alert. Let's assume I have an IDS rule says that when Facebook is accessed trigger an alert. I want to make a rule in siem also to Trigger to te…

---

## [Elasticsearch node is at 100% disk usage, unable to edit configuration](https://discuss.elastic.co/t/elasticsearch-node-is-at-100-disk-usage-unable-to-edit-configuration/351017)

<div class="topic-metadata">

**Author:** [@Sanskar\_Panchal](https://discuss.elastic.co/u/Sanskar_Panchal)\
**Replies:** 5\
**Last updated:** [January 14, 2024, 4:18pm UTC](https://discuss.elastic.co/t/elasticsearch-node-is-at-100-disk-usage-unable-to-edit-configuration/351017 "2024-01-14T16:18:45Z")

</div>

Hi, One of my Elasticsearch instance is at 100% disk usage. Which has resulted into NODE\_LEFT. Which then caused " This cluster has 39 unavailable primaries, 101 unavailable replicas." And cluster is now at red healt…

---

## [Sizing Elastic Stack for a PoC (security use case)](https://discuss.elastic.co/t/sizing-elastic-stack-for-a-poc-security-use-case/350733)

<div class="topic-metadata">

**Author:** [@Ammar\_Mostafa](https://discuss.elastic.co/u/Ammar_Mostafa)\
**Replies:** 6\
**Last updated:** [January 14, 2024, 2:12pm UTC](https://discuss.elastic.co/t/sizing-elastic-stack-for-a-poc-security-use-case/350733 "2024-01-14T14:12:04Z")

</div>

Hello Everyone, I was asked to make a PoC to show the capability the Elastic as a SIEM so the PoC will take logs from (Fortigate Firewall, Two WIndows PCs, one Windows server for file sharing) So I will setup Elasticsea…

---

## [Illegal\_argument\_exception: index.lifecycle.rollover\_alias \[actions-logs\] does not point to index \[actions-logs\]](https://discuss.elastic.co/t/illegal-argument-exception-index-lifecycle-rollover-alias-actions-logs-does-not-point-to-index-actions-logs/350916)

<div class="topic-metadata">

**Author:** [@emoxam](https://discuss.elastic.co/u/emoxam)\
**Replies:** 7\
**Last updated:** [January 14, 2024, 11:04am UTC](https://discuss.elastic.co/t/illegal-argument-exception-index-lifecycle-rollover-alias-actions-logs-does-not-point-to-index-actions-logs/350916 "2024-01-14T11:04:16Z")

</div>

Got a template with this { "index": { "lifecycle": { "name": "logstash-policy", "rollover\_alias": "actions-logs" }, "number\_of\_replicas": "0" } } Got index with name "actions-logs" But at index "actiong-logs…

---

## [Elastic Agent](https://discuss.elastic.co/t/elastic-agent/350581)

<div class="topic-metadata">

**Author:** [@Marcus\_Berglund](https://discuss.elastic.co/u/Marcus_Berglund)\
**Replies:** 3\
**Last updated:** [January 14, 2024, 9:59am UTC](https://discuss.elastic.co/t/elastic-agent/350581 "2024-01-14T09:59:51Z")

</div>

Hi, My goal is to collect system metrics for a server e.g CPU, Disk etc. I have installed the elastic agent on the server and it show up as healthy in fleet server but there are no metrics. Do I really need to install m…

---

## [Pull logs from filebeat instead of pushing by filebeat](https://discuss.elastic.co/t/pull-logs-from-filebeat-instead-of-pushing-by-filebeat/351016)

<div class="topic-metadata">

**Author:** [@Sohrab.p72](https://discuss.elastic.co/u/Sohrab.p72)\
**Replies:** 2\
**Last updated:** [January 13, 2024, 7:55pm UTC](https://discuss.elastic.co/t/pull-logs-from-filebeat-instead-of-pushing-by-filebeat/351016 "2024-01-13T19:55:23Z")

</div>

Hi, I need elk to pull data from filebeat it means I don't want the data be pushed by Filebeat to any endpoint. Like Node\_exporter for Prometheus which is listening on an endpoint for prometheus, I want filebeat or any…

---

## [Elasticsearch incomplete logs](https://discuss.elastic.co/t/elasticsearch-incomplete-logs/350899)

<div class="topic-metadata">

**Author:** [@Krishna94](https://discuss.elastic.co/u/Krishna94)\
**Replies:** 1\
**Last updated:** [January 13, 2024, 1:37pm UTC](https://discuss.elastic.co/t/elasticsearch-incomplete-logs/350899 "2024-01-13T13:37:32Z")

</div>

Hi, I have filebeat to read my inputs and logstash is the shipper to elasticsearch. But could found that the data in filebeat is not sending to elasticsearch completely. Pls do help. Thank you Athira Krishna

---

## [Elastic Agent and index names](https://discuss.elastic.co/t/elastic-agent-and-index-names/350985)

<div class="topic-metadata">

**Author:** [@wrender1](https://discuss.elastic.co/u/wrender1)\
**Replies:** 5\
**Last updated:** [January 13, 2024, 1:21pm UTC](https://discuss.elastic.co/t/elastic-agent-and-index-names/350985 "2024-01-13T13:21:30Z")

</div>

I'm deploying the Elastic Agent in standalone on Kubernetes. I've got he default yaml file, but I'm having a hard time with the index naming that it creates. It is a little unclear to me from the documentation. Do the i…

---

## [Do not alert for no data for decommissioned server](https://discuss.elastic.co/t/do-not-alert-for-no-data-for-decommissioned-server/350997)

<div class="topic-metadata">

**Author:** [@Kodito](https://discuss.elastic.co/u/Kodito)\
**Replies:** 4\
**Last updated:** [January 13, 2024, 10:41am UTC](https://discuss.elastic.co/t/do-not-alert-for-no-data-for-decommissioned-server/350997 "2024-01-13T10:41:08Z")

</div>

My cluster fires a kibana alert when there is no metricbeat data for a server for the last 15 minutes, which is very useful in the case where there is an issue with the beat/server. However, when a server is decommissio…

---

## [installing SIEM in ELK](https://discuss.elastic.co/t/installing-siem-in-elk/350008)

<div class="topic-metadata">

**Author:** [@Maksim\_Alchinov](https://discuss.elastic.co/u/Maksim_Alchinov)\
**Replies:** 1\
**Last updated:** [January 13, 2024, 9:55am UTC](https://discuss.elastic.co/t/installing-siem-in-elk/350008 "2024-01-13T09:55:14Z")

</div>

Hello, I have installed the EKL stack on my test stand, for further work and analysis of logs we need to install SIEM. How can this be done? How can I load correlation rules for log analysis?

---

## [Rollover Index Throws Exception](https://discuss.elastic.co/t/rollover-index-throws-exception/349687)

<div class="topic-metadata">

**Author:** [@krish1](https://discuss.elastic.co/u/krish1)\
**Replies:** 1\
**Last updated:** [January 13, 2024, 9:52am UTC](https://discuss.elastic.co/t/rollover-index-throws-exception/349687 "2024-01-13T09:52:04Z")

</div>

I have an index which uses ILM. The index rolls over every week. We use Spring-data to read and write for Elasticsearch. My index just rolled over today and we are having trouble with writing to it. It fails with the fol…

---

## [A node in my elasticsearch has full disk](https://discuss.elastic.co/t/a-node-in-my-elasticsearch-has-full-disk/350811)

<div class="topic-metadata">

**Author:** [@Tai\_Nguyen\_Huu](https://discuss.elastic.co/u/Tai_Nguyen_Huu)\
**Replies:** 1\
**Last updated:** [January 13, 2024, 9:12am UTC](https://discuss.elastic.co/t/a-node-in-my-elasticsearch-has-full-disk/350811 "2024-01-13T09:12:49Z")

</div>

Hi all, I have a elasticsearch cluster with 10 node, one node in my elasticsearch had full disk and it was removed from cluster by elasticsearch. the Disk of other nodes in my cluster still have 70% disk. How to I can re…

---

## [How to configure login kibana custom file build version 8.5.0?](https://discuss.elastic.co/t/how-to-configure-login-kibana-custom-file-build-version-8-5-0/351004)

<div class="topic-metadata">

**Author:** [@Cody-Test](https://discuss.elastic.co/u/Cody-Test)\
**Replies:** 0\
**Last updated:** [January 13, 2024, 4:50am UTC](https://discuss.elastic.co/t/how-to-configure-login-kibana-custom-file-build-version-8-5-0/351004 "2024-01-13T04:50:09Z")

</div>

Hello Guy, I can't configure or edit the default login page of the Kibana application on Linux using the .deb package after extracting the current storage directory at /usr/share/kibana/x-pack/plugins/security/security.…

---

## [Changing winlogbeat from elasticsearch to logstash](https://discuss.elastic.co/t/changing-winlogbeat-from-elasticsearch-to-logstash/350865)

<div class="topic-metadata">

**Author:** [@MColeman](https://discuss.elastic.co/u/MColeman)\
**Replies:** 2\
**Last updated:** [January 12, 2024, 10:33pm UTC](https://discuss.elastic.co/t/changing-winlogbeat-from-elasticsearch-to-logstash/350865 "2024-01-12T22:33:11Z")

</div>

Hi, I started off a cluster with winlogbeat going directly to elasticsearch and using the pre-built dashboards. All that worked well out of the box. Now I'd like to send my winlogbeat data through logstash so I can do s…

---

## [Recreate the automatically generated certificates](https://discuss.elastic.co/t/recreate-the-automatically-generated-certificates/350987)

<div class="topic-metadata">

**Author:** [@pxeedust](https://discuss.elastic.co/u/pxeedust)\
**Replies:** 2\
**Last updated:** [January 12, 2024, 10:25pm UTC](https://discuss.elastic.co/t/recreate-the-automatically-generated-certificates/350987 "2024-01-12T22:25:55Z")

</div>

Sorry for the beginner question, but I am having trouble regenerating the certificates that were made at deployment. I'm not familiar with how certificates work so I was hoping there might be a script that just regenerat…

[Previous page](https://discuss.elastic.co/latest.md?page=430)

[Next page](https://discuss.elastic.co/latest.md?page=432)
